Design Partner Program

You detect SIM swaps.
But what happens next?

Deploy PasskeyBridge in shadow mode—read-only, zero-PII, alongside your existing carrier signals. See what automated threat response looks like before you commit a single line of production code.

Evaluate withShadow modeZero PIISSF / CAEPDPoP shadow
Why join as a design partner

Evaluate the whole platform, with your real data.

Shadow-mode lets you measure PasskeyBridge against live carrier signals—no production risk, no new data agreements, no plaintext PII leaving your tenant.

Shadow-Mode Deployment

Run PasskeyBridge in read-only mode alongside your existing carrier signals, plus DPoP shadow telemetry that quantifies token-binding coverage at the api-key-auth chokepoint without rejecting unbound traffic. Zero impact on production.

In-Request Threat Response

See exactly how fast PasskeyBridge would have responded to every SIM-swap, number-port, SSF/CAEP session-revoked, and credential-change event your stack ingested—with full playbook simulation logs and structured observability metrics.

Zero PII Architecture

Phone numbers, subject identifiers, and SSF event subjects are keyed-hashed with HMAC-SHA-256 under a server-held pepper before they ever touch our infrastructure—non-enumerable, not merely digested. No plaintext PII is stored, transmitted, or logged. By design, not by policy. Sixteen patents filed.

Operational Resilience Built-In

Per-tenant quotas, SSRF-guarded safeFetch egress allowlist, asynchronous webhook delivery with HMAC-signed retries, anomaly scanner, canary mesh, and a public status page reading from shield_health_snapshots. Production-grade out of the box.

Cross-IdP Session Continuity

First-class SSF (OpenID Shared Signals 1.0) and CAEP (Continuous Access Evaluation 1.0) Transmitter and Receiver. Inbound SETs validated per RFC 8417, dispatched directly into the in-process revocation cascade with 24-hour jti idempotency.

Quantum-Ready Infrastructure

Hybrid PQC signatures (ML-DSA-65 alongside a classical ES256 / P-256 ECDSA signature layer), quantum-seeded entropy, ES256 tenant signing keys with 24-hour rotation grace windows, NF-08 spatial binding, and DPoP (RFC 9449) token binding across ES256/ES384/ES512/PS256/PS384/PS512/EdDSA.

How shadow-mode works

Prove the value before anything ships.

Three steps from a read-only signal source to a measured gap—without touching your production auth stack.

Step 01

Connect a Read-Only Signal Source

Point a copy of your existing Vonage, Twilio, or Sinch webhook traffic—and optionally an SSF stream from your IdP—at PasskeyBridge. No code changes to your production auth stack.

Step 02

Shadow-Mode Processing

PasskeyBridge ingests signals, runs DPoP shadow telemetry, executes your configured playbook, and generates a threat response—all in parallel, without affecting your users.

Step 03

Review & Compare

Access a real-time dashboard showing what PasskeyBridge would have done vs. what your current system did. Measure the gap in response time, coverage, and DPoP enforcement readiness.

What design partners get

Founding-partner access, end to end.

Every pillar, every signal path, and a direct line to the engineers building them.

Founding-partner commercial terms (negotiated per engagement)
Dedicated Slack channel with founding engineers
Full access to all three pillars: Network Attestation, VC Engine, and Passkeys
SSF/CAEP Transmitter + Receiver with in-process cascade dispatch
DPoP shadow mode + 5-minute enable quickstart
Per-tenant quotas, safeFetch egress allowlist, and anomaly scanner visibility
Public component-level status page (shield_health_snapshots)
Co-marketing opportunity: case study + joint blog post
Input on API design and compliance documentation
Apply

Apply for early access.

We’re accepting a limited cohort of Series A–C companies across fintech, defense, healthcare, and critical infrastructure.

Design Partner Application

Tell us about your identity challenges. Applications are reviewed within 48 hours.

Questions? Email partners@passkeybridge.io.